Arbitrary File Read Affecting rendertron-middleware package, versions <0.1.3
Threat Intelligence
EPSS
0.19% (58th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-RENDERTRONMIDDLEWARE-72701
- published 18 Dec 2018
- disclosed 17 Dec 2018
- credit Unknown
Introduced: 17 Dec 2018
CVE-2017-18354 Open this link in a new tabHow to fix?
Upgrade rendertron-middleware
to version 0.1.3 or higher.
Overview
rendertron-middleware is an Express middleware for Rendertron
Affected versions of this package are vulnerable to Arbitrary File Read. An alternative protocols such as file://
introduced a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote attacker.
References
CVSS Scores
version 3.1